[00:00.500 --> 00:05.180] So far, and I guess anybody who sat in on the last talk knows me as Mike Davis now, so secret's out. [00:07.260 --> 00:14.120] So yeah, I'm here to talk about secure instant messaging, and for some reason it seems I have to explain why people need to secure instant messaging. [00:14.680 --> 00:25.940] So, I'm going to start with the simple fact that each and every one of you that used instant messenger during this con has had your aim packets captured, stored, and are on my laptop right now. [00:28.260 --> 00:35.980] If anybody, you know, would like to see a log of what I have on AOL, MSN, or Yahoo, I can bring that up on the screen if you want. [00:38.460 --> 00:51.760] I'm not going to... the packets that I am going to dump today aren't going to be... all the packets that I'm going to use are censored mostly, so it's not enough to tell, you know, phone numbers, email addresses, or anything like that, but if you actually want me to dump your traffic, [00:51.820 --> 00:53.360] I'll be happy to dump it on the screen. [00:58.080 --> 00:58.360] Okay. [00:59.580 --> 01:00.720] Is there any way to fix that? [01:06.080 --> 01:07.660] So yeah, I wrote my talk in about an hour. [01:07.900 --> 01:12.660] If anybody is at our apartment last night, the Hacker Halfway House, you know why I wrote it in about an hour. [01:16.480 --> 01:17.240] We, uh... [01:19.540 --> 01:21.040] I can make the phone bigger. [01:25.300 --> 01:29.640] Yeah, sorry, I don't have PowerPoint, HTML, and H1 tags are about all I've got at the moment. [01:29.640 --> 01:35.200] Uh, so yeah, uh, in the year 2000, I wrote, uh, wrote a small program called Blame. [01:35.380 --> 01:38.040] It was a blowfish, uh, for AOL Instant Messenger. [01:38.340 --> 01:46.440] It, uh, used a 2K-bit Diffie-Hellman key exchange and a 448-bit, uh, blowfish for the symmetric cipher. [01:47.200 --> 01:49.860] Uh, this was mostly done for a joke. [01:50.940 --> 02:02.180] Nobody at the time had a secure instant messenger, and it was kind of a silly, frivolous thing to do to throw a lot of encryption at something as silly as a message you send to say, Hey, I'm on my way home. [02:02.860 --> 02:09.840] Uh, but in the year 2000, apparently a couple of other companies had started doing things like, uh, secure instant messaging. [02:09.840 --> 02:17.540] But the only people who had actually done it are AOL ScriptKiddies, who actually released a program called DinoChat. [02:18.200 --> 02:23.660] DinoChat used a secure, a static, uh, exclusive or key, which was actually set to secret. [02:24.020 --> 02:33.280] Uh, the program itself worked by hooking, uh, hooking Windows messages in the AOL chat rooms in that crappy, crappy AOL dial-up program. [02:34.100 --> 02:35.800] Um, it annoyed a lot of people. [02:35.960 --> 02:37.980] Nobody really used it, and it disappeared rather quickly. [02:38.920 --> 02:49.940] Uh, Silk was an encrypted IRC client, if you want to count IRC as an instant messenger, which my buddy has kind of pointed out as arguably considered instant messaging, but hey, whatever. [02:50.380 --> 02:53.460] They still came out with it about a month after Blame was released. [02:53.760 --> 02:57.540] Uh, Blame is my particular program. [02:57.740 --> 03:02.320] It's a 2048-bit DH, a 448-bit Blowfish, went through all that. [03:02.320 --> 03:09.400] I later on decided that, after the dot-com bust, I could probably, you know, make a buck off of this kind of thing, because nobody else had it. [03:10.320 --> 03:18.400] And, uh, I released Impass, which was 3072-bit RSA, 448-bit Blowfish, ran only under Windows, and, well, sucked. [03:19.020 --> 03:22.320] Uh, later on we started getting a lot more imitators. [03:22.460 --> 03:23.880] You can kind of read the list for yourself. [03:23.880 --> 03:28.980] Uh, the more and more recent that they get, the crappier and crappier that they actually get. [03:29.220 --> 03:36.140] Uh, lower and lower key lengths, and, if you see on the last two, I stopped listing them, there's actually more instant messaging clients. [03:36.500 --> 03:41.040] Uh, there's actually, you know, no mention of what type of encryption they use whatsoever. [03:41.260 --> 03:47.100] No key lengths, no, you know, so it's just uber-secret encryption, trust us, we'll keep everything secure for you. [03:47.740 --> 03:50.540] Hey, I can't, you know, say they're lying, right? [03:51.460 --> 03:57.660] Uh, also, at the time, uh, I was releasing Blame, AOL, or, sorry, Impass. [03:58.140 --> 04:07.040] AOL had promised a lot of, uh, supporters that, uh, basically they were going to release a enterprise edition of AOL Instant Messenger. [04:07.320 --> 04:17.420] The enterprise edition was supposed to be the magical all-in-wonder gateway that everyone could use to keep all of their instant messages secure, and only, of course, AOL would be able to sniff the traffic. [04:17.680 --> 04:18.440] We all trust AOL. [04:19.360 --> 04:25.540] Uh, they never actually released an encryption package with their enterprise messaging, they only released a gateway. [04:26.020 --> 04:31.640] They later on told people that it was coming, it was coming, it was coming, basically killing my business entirely. [04:32.000 --> 04:34.540] Uh, and they never actually released it. [04:34.880 --> 04:41.800] They later on, as this is probably cut off on the bottom of the screen, actually in the last few months, sold their company to Iconic Systems. [04:42.160 --> 04:45.640] Iconic Systems specialized in logging instant message gateways. [04:46.080 --> 04:47.980] Or, yeah, logging instant message gateways. [04:49.240 --> 04:53.980] Basically, they log every instant message for, quote, SEC compliance, and, well... [04:55.840 --> 05:00.140] I don't know if you can trust your encryption to a company that, you know, specializes in logging. [05:01.720 --> 05:15.120] Uh, anyway, going back a little bit to Blame, I, uh, had a little bit of a problem with Blame, in that AOL was trying to release their, uh, commercial version of the software, and they tried pushing me out of business. [05:15.900 --> 05:20.400] So, what we actually ended up with was my very first cease and desist. [05:20.500 --> 05:21.680] I'll see if I can make that a little bit bigger. [05:25.440 --> 05:26.360] Uh, I'm working on it. [05:26.420 --> 05:26.620] Hold on. [05:29.160 --> 05:30.860] Uh, oh, control plus. [05:33.420 --> 05:35.640] Uh, yeah, I don't know that you actually want to read this thing. [05:35.640 --> 05:41.880] It's basically saying that, uh, I can't call my software Blame, because they own any word that ends in AIM. [05:42.620 --> 05:48.960] Uh, they also serve notices to, uh, project organizers of GAME, which you probably use. [05:49.120 --> 05:52.600] NAME, TAME, N-TAME, and all the other derivatives. [05:53.400 --> 05:55.520] But, uh, they went after me particularly hard. [05:55.680 --> 06:00.780] GAME got to actually keep their name, while GAME, or Blame itself, was blacklisted. [06:00.780 --> 06:02.680] I could no longer keep my project on SourceForge. [06:03.100 --> 06:11.500] Uh, the company that owned it at the time, VA Linux, uh, said that I'm welcome to get a lawyer, but that they're not going to put my project back up. [06:13.200 --> 06:14.380] Hey, no more encryption. [06:14.680 --> 06:16.600] Uh, a lot of people actually complained about this. [06:16.680 --> 06:20.400] I found newsgroup posting after newsgroup posting about why people can't encrypt. [06:20.480 --> 06:22.360] And this is, uh, one of the reasons why. [06:22.780 --> 06:23.940] They, they kind of suppressed this thing. [06:25.040 --> 06:28.940] Uh, so, I started producing in pass. [06:29.300 --> 06:29.900] Yada, yada, yada. [06:31.020 --> 06:31.960] I shouldn't use that. [06:32.600 --> 06:33.340] Uh, yada, yada, yada. [06:33.500 --> 06:38.880] A company came along and said, hey, we noticed you're making this really cool instant messaging encryption software. [06:39.060 --> 06:46.380] And to give you an idea of what people think of securing their instant messages, this company, and, uh, this is an uncensored email. [06:48.300 --> 06:49.100] Oh, I don't care. [06:49.240 --> 06:50.160] I actually did this deliberately. [06:50.420 --> 06:57.620] Uh, an uncensored email from a company who wanted to add spyware to my instant messaging package. [06:57.940 --> 07:02.540] I, I don't know if that seems like a, a conflict to anyone else, but... [07:04.100 --> 07:05.480] Yeah, so, so take a look. [07:05.600 --> 07:06.120] That's, uh, what? [07:06.240 --> 07:08.840] Jay Beck at Lions Pride Enterprises. [07:09.420 --> 07:11.600] Feel free to email these guys whenever you want. [07:14.480 --> 07:16.040] Email them as much as you want, actually. [07:16.360 --> 07:21.140] Um, so now moving on to why I have to actually explain that secure instant messaging is totally insecure. [07:21.140 --> 07:23.240] Um, multiple reasons, actually. [07:23.740 --> 07:27.800] First of all, is that every single instant messaging protocol is done in the clear. [07:30.360 --> 07:31.480] Let's see if I can... [07:31.480 --> 07:35.360] I don't know if anybody can read that, but these are actually captures that I got during the con. [07:35.500 --> 07:42.660] I abused my, uh, knock privileges to dump all your traffic as easily as your ISP or anyone else upstream could. [07:43.220 --> 07:45.740] Uh, even your roommates are probably doing something like this. [07:45.960 --> 07:48.000] So if you take a look at these, a lot of these are really good. [07:48.000 --> 08:03.180] Uh, the first two packet captures came during the Emmanuel Goldstein's, uh, off the hook talk, where he mess, uh, mentioned that, uh, these Pepsi cell phone, or Coke cans, whatever it was, uh, had a little cell phone and GPS transceiver inside, or, uh, [08:03.660 --> 08:08.620] transmitter, receiver, whatever, inside of them, and, uh, that the military is basically going apeshit over it. [08:09.180 --> 08:11.000] And this is somebody sitting on the talk. [08:11.400 --> 08:13.380] I've censored their name with X's there. [08:13.520 --> 08:15.280] You can brute force that if you feel like it. [08:15.800 --> 08:19.660] Uh, basically saying that, oh yeah, we're not allowed to bring them in a secure area. [08:19.660 --> 08:21.640] So maybe that's a fed and you might want to spot him. [08:24.240 --> 08:25.280] Uh, let's see. [08:25.560 --> 08:27.880] Other people appreciating the wireless bandwidth. [08:28.980 --> 08:34.100] Oh yeah, my favorite are, are the ones at the, in the very bottom here that, uh, your conversation is not secure on this network. [08:35.380 --> 08:36.740] This network is not secure. [08:36.920 --> 08:38.400] And they just keep going on and on and on. [08:38.740 --> 08:48.000] Uh, I was even able to capture packets from, uh, you know, our good friend Dragorn, who, uh, happens to have written Kismet, and knows well about the problems there. [08:48.380 --> 08:49.660] With things like instant messaging. [08:50.260 --> 08:55.100] Uh, other things, uh, I know I promised I'd censor some of that, but that's somebody's phone number I forgot to censor. [08:55.280 --> 08:57.000] Just ignore that, pretend it's not there. [08:58.620 --> 09:02.560] Uh, there's a, a packet down, yeah, like I said, I wrote it in an hour, sorry. [09:02.560 --> 09:05.080] Um, whatever. [09:06.120 --> 09:07.120] Somebody censor it later. [09:07.960 --> 09:10.360] Um, down at the bottom basically, somebody else doing the same thing. [09:10.480 --> 09:13.900] I am downloading EtherApe and saying how cool of a program it is. [09:14.600 --> 09:16.820] Uh, hey, that's, that's cool, great. [09:16.980 --> 09:17.880] So I dumped your packets. [09:18.240 --> 09:20.920] Um, that's one of the ways in which instant messaging is vulnerable. [09:21.140 --> 09:22.240] It's, it's a pretty simple one. [09:22.340 --> 09:23.100] I can read your packets. [09:23.260 --> 09:25.620] We've known this for ages, but companies kind of ignore it. [09:25.660 --> 09:26.640] They pretend it doesn't exist. [09:26.780 --> 09:27.460] It's not a problem. [09:27.800 --> 09:37.940] And the few companies that actually do, like SBC Global, try to reach out and get instant messaging, they were duped by AOL into waiting and waiting and waiting and now still currently have no secure instant messaging solution. [09:38.220 --> 09:47.720] So up to 300,000 employees that they had intended on securing with secure instant messages are completely going, you know, over the clear and not being filtered. [09:47.720 --> 09:49.960] Uh, because I didn't load. [09:50.200 --> 09:51.920] Uh, because I didn't load. [09:52.400 --> 09:52.800] HTML. [09:53.560 --> 09:54.280] This file. [09:55.760 --> 10:05.020] Uh, some other things that I actually noticed while I was doing this, uh, is that there's, there's likely a format string exploit in the AOL protocols themselves. [10:05.260 --> 10:05.980] It's, it's pretty clear. [10:06.180 --> 10:07.000] It's, uh, at the bottom. [10:07.140 --> 10:08.920] Is there anybody if we can actually move that last one up? [10:11.720 --> 10:12.120] Anybody? [10:12.400 --> 10:12.800] Projector? [10:12.980 --> 10:13.180] Somebody? [10:13.360 --> 10:13.540] All right. [10:13.660 --> 10:13.960] Well, whatever. [10:13.960 --> 10:22.220] Uh, basically, AOL gives a URL to the client and uses that URL as a direct entry into printf. [10:22.540 --> 10:27.160] And at the very last, the, the, the very first argument that they have is a percent S. [10:27.400 --> 10:40.240] If you know anything about format string exploits, percent S can be changed into a whole bunch of percent X's, percent U's, and eventually percent N's and overriding EIP and, well, you can figure out the rest. [10:40.240 --> 10:45.440] Uh, the other part of it is that the passwords are actually sent as MD5 passwords. [10:45.720 --> 10:47.780] Uh, they're just simple MD5 crypts. [10:47.940 --> 10:56.940] Uh, but unfortunately, most people only use five to six digit passwords, which are pretty easily brute forced with, uh, I think, uh, MD5 crack is one of the programs. [10:57.180 --> 10:59.780] Uh, NGSEC makes a program that also brute forces these. [11:00.000 --> 11:04.300] You could probably brute force a, a five digit password in, you know, a few hours. [11:04.740 --> 11:07.940] Six to seven digit password may take you a few more hours, maybe a day. [11:07.940 --> 11:09.800] It's, you kind of get the idea. [11:10.060 --> 11:15.240] And how many of you actually use the same password on your instant messenger that you use to log into your, your box at home? [11:16.400 --> 11:17.620] I'm not gonna put anyone out. [11:19.400 --> 11:22.500] Uh, you also see here that there's plugins for AOL instant messenger. [11:22.620 --> 11:24.420] This very last packet right here. [11:25.280 --> 11:29.580] Uh, this is also kind of dangerous because it's doing the same thing that AOL is doing and using a percent N. [11:29.700 --> 11:35.480] And I have it, uh, in a different area because I, I'm using it to show off that I can tell what type of software you're running. [11:35.960 --> 11:39.600] Uh, but this percent N is also pretty easily exploitable. [11:39.800 --> 11:48.080] So long as you can edit the package stream and were I actually running the firewall myself, I could have filtered packets and change those percent Ns into something a little bit more malicious. [11:48.600 --> 11:57.280] And the way I would have been able to do that is because I also know the exact version number you're using and the exact version of Windows that you're using because for some reason AOL is curious in that. [11:58.300 --> 12:07.680] I also know the architecture of your system, the exact build number of your Windows, and I know this is also a pirated version of Windows because it's the .2600 build. [12:10.420 --> 12:12.000] Uh, what else do I have here? [12:16.090 --> 12:17.890] I had something else here, but I lost it. [12:18.090 --> 12:24.710] Uh, well I guess that's kind of the, the end of my little cute, uh, I've shown you that I've exploited everyone at the con kind of thing. [12:24.710 --> 12:28.830] Uh, if anyone actually wants me to dump their traffic, I'd be happy to do that. [12:29.030 --> 12:30.790] I don't know if anybody wants to volunteer for it. [12:31.830 --> 12:32.410] I guess. [12:42.740 --> 12:43.380] On AOL? [12:43.840 --> 12:44.160] Uh-huh. [12:45.480 --> 12:47.000] How do you, uh, how do you actually do that? [12:48.200 --> 12:48.600] MRB00. [12:49.820 --> 12:50.220] Oops. [12:51.760 --> 12:52.640] I can't type. [12:53.380 --> 12:53.780] MRB00. [12:55.400 --> 12:56.100] The rest of it? [12:56.740 --> 12:57.860] No, that's probably not. [13:13.140 --> 13:14.160] No, just a little nervous. [13:14.160 --> 13:16.160] How much data did you stop? [13:16.660 --> 13:19.820] Uh, I actually dumped a little over 70 gigs of AIM traffic. [13:20.180 --> 13:22.420] Uh, not just, or, sorry, 70 gigs. [13:22.500 --> 13:23.520] 70 meg of AIM traffic. [13:23.940 --> 13:26.000] Uh, not just AOL. [13:26.220 --> 13:32.540] Uh, I mostly have a complete set of AOL data from the moment the network came up to about an hour before my talk. [13:32.760 --> 13:37.580] Uh, I also started capturing at a later point Yahoo and MSN traffic. [13:37.580 --> 13:38.900] I didn't get to go through those packets. [13:39.320 --> 13:41.340] Uh, but I'll probably go through them later. [13:41.480 --> 13:42.420] Read all your conversations. [13:42.640 --> 13:43.560] How many of you are comfortable with that? [13:43.720 --> 13:44.480] Any, any questions? [13:46.500 --> 13:52.880] Uh, I actually did not find a single person using Game E or Blame or any other secure instant messaging package. [13:53.040 --> 14:00.620] Most people were using, uh, um, the Mac OS X client iChat or, uh, one of the other open source clients. [14:00.620 --> 14:02.820] I actually found very few open source clients on the network. [14:02.940 --> 14:06.160] So most of you are running either IMAX or Windows 2000 machines. [14:06.320 --> 14:07.600] I'm really disappointed in you all. [14:08.580 --> 14:08.620] Um. [14:09.320 --> 14:10.040] What about ICQ? [14:10.340 --> 14:16.000] Uh, I didn't see a lot of ICQ, but ICQ is, is very hard to distinguish from AOL. [14:16.280 --> 14:20.760] Since AOL purchased ICQ and moved ICQ over to the OSCAR protocol. [14:21.080 --> 14:26.580] Uh, which is supposed to be an open protocol because it's actually named an open protocol. [14:26.580 --> 14:30.600] But it is not and, you know, they moved their client over to it. [14:30.680 --> 14:32.400] The only difference between ICQ... [14:34.460 --> 14:38.060] ICQ uses, uh, uh, uh, RTF instead of HTML. [14:38.980 --> 14:42.300] And, uh, that's, that's kind of it. [14:42.360 --> 14:44.900] They also don't allow, uh, binary contents in their packets. [14:45.120 --> 14:46.440] Uh, AOL for some reason does. [14:47.740 --> 14:50.240] I think that's probably for those little buddy icons. [14:50.540 --> 14:53.280] Feel comfortable with, uh, binary contents coming in also. [14:54.080 --> 14:58.400] Uh, it's not a PCAP filter. [15:10.730 --> 15:13.810] Is, uh, Mr. Buddy capitalized at all like that? [15:14.190 --> 15:14.990] I don't know. [15:15.410 --> 15:15.730] Oh. [15:23.640 --> 15:29.180] Uh, what you see here also are, uh, people's buddy lists actually loading and refreshing. [15:29.460 --> 15:31.460] Uh, I don't really... [15:31.460 --> 15:34.920] You can feel free to add all these guys to your buddy list at home. [15:35.320 --> 15:41.340] Um, but, but if you, you want to have an idea of the amount of data that I actually captured during this. [15:41.620 --> 15:45.420] Uh, uh, 5190. [15:45.560 --> 15:47.840] This is just the, the AOL packet itself. [15:49.400 --> 15:50.620] The AOL packets themselves. [15:55.700 --> 15:57.980] It's, uh, a lot of data including most of your passwords. [15:58.340 --> 16:00.980] Uh, there's also a lot of people checking their POP3 email. [16:01.180 --> 16:02.200] What the fuck is wrong with you people? [16:04.400 --> 16:10.200] Uh, if it makes you feel any better though, the only data that's, uh, actually kept is, uh, the, uh, instant messaging data. [16:10.860 --> 16:13.100] Uh, if you're not happy with that, let me know. [16:13.280 --> 16:14.020] I'll actually delete it. [16:14.100 --> 16:21.560] I only really wanted to do this during the con because it's, uh, it has far more impact when you can show people their actual packets, uh, up on the screen. [16:25.620 --> 16:26.160] Excuse me? [16:27.340 --> 16:29.460] Uh, I don't know if anybody was doing VPN out. [16:29.580 --> 16:37.340] I just stuck to, uh, very basic filters of watching port 5190 5050 and 5163 for, uh, MSN Messenger. [16:37.760 --> 16:43.280] Uh, MSN Messenger is actually the hardest protocol to read if you're going to be stealing packet, or sniffing packets. [16:43.420 --> 16:48.240] If you take a look at this packet right here, which actually, it's, uh, hopefully you can't read this guy's name. [16:48.240 --> 16:53.400] But, uh, the packets are just, uh, HTML format packets, and you can read the HTML right out of the packet. [16:53.560 --> 16:54.860] There's nothing really complicated in it. [16:55.360 --> 17:08.720] Uh, MSN Messenger protocol is, is far easier to read because it uses a HTML header file and, uh, basically says, our message is going to be 163 bytes long, and here's the plain text message with no other formatting added to it, other than HTML escapes. [17:10.040 --> 17:14.540] Uh, I guess that's kind of the end of this particular, oh, wait, wait, wait. [17:17.880 --> 17:20.020] If, if you want to ask something, you might want to go to the mic. [17:20.140 --> 17:21.180] I can't really hear you too well. [17:21.880 --> 17:26.780] Uh, hopefully, if anybody else has any questions, like, come up, because, uh, I work much better when people ask me. [17:27.160 --> 17:31.360] How does the MSN Messenger password encryption compare to the AMP password encryption? [17:31.500 --> 17:34.020] Um, actually, they use something very similar. [17:34.200 --> 17:35.700] They, they're both using something it can do. [17:35.860 --> 17:41.660] Either MD5 directly, or using some simple variation MD5, like switching the byte order of, of something. [17:42.340 --> 17:42.780] Um... [17:42.780 --> 17:43.520] Uh, [17:47.980 --> 17:50.800] MSN has actually gone through a whole lot of, uh, of changing. [17:50.960 --> 17:56.240] They're actually working to try to have, uh, some sort of encryption infrastructure built into their, their messaging. [17:56.880 --> 18:00.300] But it's, so far, not an end-to-end encryption solution. [18:00.440 --> 18:03.000] AOL has always seemed to work themselves into the protocol. [18:03.120 --> 18:05.580] MSN has also seemed to work themselves into the protocol every time. [18:06.240 --> 18:12.360] AOL, however, seems to be the only company that seems to try to force people not to mess with the package stream. [18:12.500 --> 18:17.460] They, they include things like their, your own sequence header, or sequence numbers for individual conversations. [18:18.120 --> 18:21.800] Um, I can't really speculate as to why, but I'm a paranoid guy. [18:22.000 --> 18:28.060] And I speculate that it's easier to put together conversations later when each message has a sequence number and a time date stamp in the header. [18:29.760 --> 18:31.460] Uh, any, anybody else have any other questions? [18:37.100 --> 18:43.510] I was under the impression that at one point, um, AOL was using a XOR, uh, encryption. [18:44.340 --> 18:47.950] Uh, earlier on, AOL, possibly, I, it might be the TOC protocol. [18:48.120 --> 18:48.910] I could be wrong. [18:49.040 --> 18:50.230] There, there's two protocols to AOL. [18:50.340 --> 18:52.360] There's the TOC protocol and then there's the OSCAR protocol. [18:52.910 --> 18:55.580] TOC itself is very minimalist protocol. [18:55.790 --> 18:58.430] It was, you know, written for a Java client initially. [18:58.430 --> 19:08.210] And they've, they've upgraded, downgraded over the years to this binary monster that is, you know, packets hidden within packets, within packets. [19:08.390 --> 19:15.600] And tree level structures and sequence numbers and, uh, all kinds of dead space in packets that are reserved for things. [19:15.750 --> 19:16.840] There, there are also other things. [19:16.970 --> 19:17.970] Oh, I have something else I do want to share. [19:17.970 --> 19:25.170] There, there are also other things that AOL has added to their packets to prevent other clients from connecting to their network. [19:25.450 --> 19:31.360] And, basically, trying to be really mean about who can connect to their network. [19:31.510 --> 19:32.490] I don't know the name of this file. [19:32.750 --> 19:33.410] So, hang on a second. [19:37.900 --> 19:38.230] Uh. [19:43.620 --> 19:44.500] Oh, yeah. [19:46.960 --> 19:48.840] I hate AOL.HTML. [19:53.560 --> 19:54.100] So, yeah. [19:54.720 --> 20:03.520] When AOL initially tried locking out its, uh, the open source clients, uh, by adding things like, uh, MD5, or not actually MD5 something, sorry. [20:03.680 --> 20:06.880] But, but hashing the binaries of AIM themselves. [20:07.080 --> 20:09.960] This is, uh, this is kind of the AIM guys, or the game guys' response. [20:10.140 --> 20:16.400] If you, you want to look at the name of the structures, then, and the two functions that it took to work around AOL, as well as, uh, changing of the protocol here. [20:16.940 --> 20:18.420] It's a piece of crap. [20:18.600 --> 20:19.080] Damn you. [20:19.400 --> 20:21.300] And go straight to hell, or straight to hell. [20:21.940 --> 20:29.180] Uh, a lot of this was, uh, worked around by actually storing the binaries on the AOL, or on, uh, the SourceForge game servers. [20:29.320 --> 20:30.380] And AOL actually never looked. [20:30.520 --> 20:38.920] They, they probably could have had it pulled down because it's a violation of their little terms of service to actually store these binaries and use them in any other way than what was directed. [20:39.100 --> 20:43.960] But, game actually allowed you to hit their site and hit the CGI that's, that's still there, actually. [20:44.480 --> 20:51.100] That will, uh, give you the hash for any, uh, of the, the sections of the source, or, of the, uh, binary that AOL is requesting. [20:52.080 --> 20:54.700] It's, uh, one of the many ways they do it. [20:54.780 --> 20:57.660] I'd also show you one of these, uh, actual packets. [20:57.840 --> 21:07.040] But they started adding things like a very small packet that the LIB fame guys, the guys who actually implemented OSCAR for open source, uh, used, basically. [21:07.040 --> 21:11.720] Uh, this little small packet, nobody really knew the contents of the packet. [21:11.880 --> 21:14.820] It was, uh, TLV type five, I believe. [21:15.160 --> 21:17.080] And it could be either three or four bytes long. [21:17.380 --> 21:20.240] And they began implementing it as a, a four byte long packet. [21:20.780 --> 21:22.800] And the open source clients immediately picked up. [21:22.880 --> 21:25.840] And because they don't truly understand the protocol, they, they threw that in there. [21:25.920 --> 21:28.220] They just, we don't understand what this does, but it's in every packet. [21:28.360 --> 21:29.320] The server won't accept it. [21:29.320 --> 21:33.920] AOL then began switching all of its clients to use a length of three for that packet. [21:34.160 --> 21:37.540] They were able to actually distinguish all of the people using open source clients. [21:37.800 --> 21:38.940] And began blocking on that. [21:39.640 --> 21:43.680] Uh, they've since stopped doing all of this blocking, you know, legal threats and other reasons. [21:44.900 --> 21:45.880] Uh, anybody else? [21:47.280 --> 21:52.000] Um, what about re-constructing video packets via MSN Messenger or Yahoo? [21:52.380 --> 21:56.180] Uh, most of the time MSN Messenger and Yahoo, it's perfectly possible. [21:56.720 --> 21:58.420] Uh, nobody's actually written a package yet. [21:58.420 --> 21:59.380] Uh, maybe I will. [22:00.060 --> 22:03.280] Uh, to actually take the raw data and reconstruct them into a video stream. [22:03.480 --> 22:06.160] Uh, but most of the time, those packets are connected client to client. [22:06.280 --> 22:08.000] They don't actually go through AOL servers. [22:08.580 --> 22:11.140] Uh, the instant messages themselves do go through AOL servers. [22:11.360 --> 22:13.300] And that's why I find them the biggest threat. [22:13.500 --> 22:20.900] Because most of the time, uh, something like AOL Instant Messenger can easily be used and is actually used by some people to circumvent firewall rules. [22:21.480 --> 22:24.880] Um, transporting files in and out of, uh, their offices. [22:24.880 --> 22:28.040] Um, I actually wrote a program before called, uh, Butter X. [22:28.280 --> 22:32.100] Which would allow you to export X terms using the AOL Instant Messenger. [22:32.580 --> 22:34.260] Uh, so... [22:34.760 --> 22:36.100] So, anything else? [22:39.120 --> 22:39.560] Uh, [22:44.720 --> 22:45.820] it won't get encrypted. [22:46.240 --> 22:54.380] Uh, one of the ways, uh, my, my software impasse that I, what I'd actually done was I lied to the AOL client and I told it that it would be using a SOCKS 4 or SOCKS 5 proxy. [22:54.380 --> 22:59.960] So, all the connections the client attempted to make would go through that proxy and all the packets would then get filtered. [23:00.220 --> 23:10.280] And it's, that's a really trivial, uh, amount of work to actually remove the contents once you understand the format of the packet, encrypt it, put it back in the packet, and have it, uh, undone on the other end. [23:10.780 --> 23:18.140] Believe it or not, a lot of people were disappointed with the idea that you actually had to have, uh, a client on both ends to encrypt the conversation. [23:18.140 --> 23:23.260] They, they were perfectly okay with having it encrypted to AOL and not encrypted for the rest of the way. [23:23.880 --> 23:30.480] Um, there are some other packets that I found during this capture, by the way, that, uh, had usernames and passwords for machines that were on the network. [23:31.120 --> 23:37.140] Um, I don't know whether they came from a wireless or a wired machine, but if they were on the wireless, somebody else probably has them. [23:37.140 --> 23:39.600] Um, just, just letting everyone know. [23:42.670 --> 24:03.990] So, in light of the fact that it seems like most people don't use open source clients, and that AOL tends to change the protocol, you know, wildly, uh, wouldn't it make more sense to do something like, make it extremely easy for people using the standard client to do something like establish an SSH tunnel, [24:04.750 --> 24:10.110] or use a, you know, probably a better idea would be to write a proxy. [24:10.610 --> 24:11.030] Mm-hm. [24:11.370 --> 24:18.610] Um, that would do, I mean, that has the problem that at the other end, then you have to have a proxy to decrypt. [24:18.790 --> 24:25.530] But, then the other challenge is to get them to actually change the server and port number in their preferences. [24:26.430 --> 24:26.750] Yeah. [24:26.850 --> 24:29.510] So, I mean, do you, do you have any, this is something I haven't been thinking about for a while. [24:29.590 --> 24:30.690] Do you have any insights on that? [24:30.750 --> 24:33.430] Uh, the way that I did it before was actually a dirty cheat. [24:33.430 --> 24:40.030] Um, and it only worked for Windows because my assumption at the time was that, uh, only Windows would make money at all. [24:40.290 --> 24:41.690] Open source just doesn't seem to make any money. [24:42.510 --> 24:44.390] Um, by the way, I didn't make any money. [24:44.570 --> 24:49.710] I, I believe I spent around, uh, 2,500 in marijuana, uh, writing Impasse. [24:49.950 --> 24:55.430] And, uh, I made about three months worth of rent on a college campus renting a room with Impasse. [24:55.650 --> 25:01.070] So, um, as far as changing the settings in any of the clients, uh, we kind of hard-coded it. [25:01.070 --> 25:02.610] We gave them a simple little check box. [25:02.770 --> 25:06.330] You can click here to activate AOL Instant Messenger to use encryption. [25:06.350 --> 25:11.550] And all it did was change a registry setting because all of these, uh, clients store this kind of information in the registry. [25:11.550 --> 25:14.790] So that if you remove it and reinstall it, you still have those settings there. [25:15.730 --> 25:16.610] Uh, anything else? [25:19.190 --> 25:19.790] All right. [25:20.050 --> 25:22.050] Well, I guess that's kind of the end of my talk. [25:22.450 --> 25:30.290] Um, if anybody, uh, wants to come up after, you know, they turn off the cameras and things and maybe turn off the, uh, the video display, I'd be happy to show them what I've actually captured. [25:32.610 --> 25:34.890] Um, otherwise, oh yeah, wait, wait, wait. [25:35.050 --> 25:36.110] Did you go on AOL Instant Messenger? [25:36.490 --> 25:38.650] I did not go on AOL Instant Messenger, no. [25:40.690 --> 25:52.650] Uh, a lot of the people that, actually a lot of smart people who did go on AOL Instant Messenger accidentally prevented me from sniffing their traffic by using SSH to SSH to another machine and then using a console client. [25:53.010 --> 25:57.290] Uh, while that may have prevented me from sniffing it, that didn't prevent Verizon from sniffing it. [25:57.290 --> 26:06.850] Uh, and before I go, since any, uh, since any of you were at my party last night, you understand that, uh, we have no money left. [26:07.050 --> 26:08.890] We spent it on 61 liters of vodka. [26:10.130 --> 26:13.830] So, uh, if you don't want to donate money to, you know, help for vodka, buy a t-shirt. [26:15.110 --> 26:18.890] Downstairs, already, uh, uh, yeah, yeah, this guy's wearing one right here. [26:20.450 --> 26:21.230] Stand up, fat man. [26:24.610 --> 26:29.250] Yeah, it's a shameless promotion, uh, to pay for vodka, because we're poor, we're haxors. [26:29.630 --> 26:30.170] Yeah, yeah. [26:30.510 --> 26:33.590] We, we, we had all you guys at our house, you destroyed it, everything's sticky now. [26:34.230 --> 26:39.310] Uh, I, I believe we also destroyed Emmanuel's room pretty badly, uh, although it looks perfect now, it's cool. [26:40.330 --> 26:44.050] Uh, alright, I'm, I'm done. [26:44.270 --> 26:46.350] Uh, I'm far, I'm gone. [26:48.790 --> 26:49.810] One quick announcement. [26:51.470 --> 26:52.490] One quick announcement. [26:52.770 --> 26:55.270] If you've enjoyed the conference, we've certainly enjoyed having you here. [26:55.790 --> 26:58.950] Uh, right now, there's a lot of stuff that needs to get cleaned up. [26:59.130 --> 27:02.070] Now, the closing ceremony's gonna start, so I certainly wouldn't want you to work through that. [27:02.190 --> 27:08.230] But if you happen to have a volunteer spirit, hang around, unstick some tape, uh, do some other stuff. [27:08.390 --> 27:10.530] Just find somebody with a red badge or carry zero. [27:10.750 --> 27:11.050] Thank you. [27:13.590 --> 27:17.790] I was also, I was actually trying to breathe in and talk about myself with it. [27:17.930 --> 27:25.710] But actually, it turns out, we had the first and last year to secure my drink, or for some of the girls.